W32/Bagle.l@MM

Discussion in 'malware problems & news' started by Marianna, Mar 9, 2004.

Thread Status:
Not open for further replies.
  1. Marianna

    Marianna Spyware Fighter

    Joined:
    Apr 23, 2002
    Posts:
    1,215
    Location:
    B.C. Canada
    Virus Information
    Discovery Date: 03/09/2004
    Origin: Unknown
    Length: Varies
    Type: Virus
    SubType: E-mail

    This is a mass-mailing worm with the following characteristics:

    contains its own SMTP engine to construct outgoing messages
    harvests email addresses from the victim machine
    the From: address of messages is spoofed
    attachment can be a password-protected zip file, with the password included in the message body.
    contains a remote access component (notification is sent to hacker)
    copies itself to folders that have the phrase shar in the name (such as common peer-to-peer applications; KaZaa, Bearshare, Limewire, etc)

    Read more: http://vil.nai.com/vil/content/v_101088.htm
     
Thread Status:
Not open for further replies.